As Age Assurance Moves Into Practice, What Can Policymakers Learn From New York?
Amy Winecoff / Sep 8, 2026
New York Gov. Kathy Hochul (center), flanked by Attorney General Letitia James (right) and supporters, holds up one of two bills she signed in July 2024 aimed at protecting children and youth from the harmful effects of social media. Photo by Susan Watts/Office of New York Gov. Source
Age assurance is becoming a common component underlying youth online safety policy. Platforms are increasingly being required to provide different features, experiences, and protections for youth, such as usage limitations or prohibitions on nighttime notifications. The success of these interventions will depend in part on how companies determine which users qualify for them, making the concrete requirements governing age assurance systems a crucial part of implementation.
In the United States, these requirements are now being defined through legislation, regulation, and litigation. Last month, a landmark multi-state settlement with Meta established detailed requirements for the age assurance framework Meta must implement to determine which users receive the court-ordered protections. Last week, California lawmakers passed a bill that, if enacted, would prohibit social media platforms from offering certain addictive features to users under 16, with key implementation requirements currently under development by the state’s Attorney General. Together, these moves underscore a broader shift: as youth online safety mandates emerge across jurisdictions, policymakers, regulators, and courts must answer the harder implementation questions of how age assurance systems should work, how their performance should be measured, and how companies should be held accountable when they fail.
New York has already begun answering many of these questions. When its Stop Addictive Feeds Exploitation (SAFE) for Kids Act passed in 2024, New York became one of the first states to task a public authority with writing rules governing how companies determine users’ ages online. The law, which is intended to limit social media companies’ use of certain “addictive” features for young users, directed the New York Attorney General to develop implementation rules that specify concrete requirements for age assurance. The final rules, released on July 28, establish requirements governing the performance, evaluation, and oversight of age assurance systems used to implement the law. At a moment when similar requirements are taking shape elsewhere, New York provides an important early model for crafting age assurance governance, and lessons for how future approaches can improve.
The New York rules establish a solid foundation. They recognize that effective age assurance cannot be reduced to a simple, one-time compliance checkbox assessed by companies themselves. Instead, an effective regime requires ongoing evaluation of companies’ systems against multiple criteria that reflect tradeoffs among efficacy, availability, privacy, and other objectives. The New York rules also enable independent auditors, public authorities, and other actors to evaluate performance and hold companies accountable.
But New York’s approach also leaves important gaps that policymakers elsewhere can learn from. Future rules should give greater weight to the consequences of incorrectly classifying eligible users as ineligible, put more emphasis on the performance of age assurance systems as a whole in addition to individual age assurance methods, and require greater public transparency about how these systems perform in practice. Filling these gaps will help policymakers elsewhere build on New York’s approach and develop stronger models for age assurance implementation.
The rules recognize that age assurance requires balancing competing values.
In several places, New York’s rules implicitly acknowledge that age assurance requirements should not focus exclusively on preventing minors from accessing restricted features, but rather, should balance that objective against other considerations, including privacy, service availability, and burdens on adult users. For instance, the rules generally require covered operators offering an age assurance method that relies on a government ID to also offer at least one non-ID alternative. If all non-ID methods offered return inconclusive results, a user who declines to provide government ID can instead proceed to the appeals process. These provisions recognize that although government IDs can provide a highly accurate age signal, not all users have access to one or are comfortable providing it as part of an age verification process.
The rules also allow a user to be presumed an adult when: (1) every age assurance method offered produces an inconclusive result; and (2) the operator has no other actual knowledge that the user is a minor. These examples show that the New York rules do not treat efficacy as the only relevant objective, but one to be balanced with other values, such as access, user choice, and privacy.
The balance of values should be supported more comprehensively in future rules.
Future rules can do more to embed consideration for the balance of values consistently throughout their requirements. For example, under the New York rules, covered operators are generally not required to provide users with multiple age assurance options, even though different methods may impose different privacy, accessibility, or usability burdens. Offering multiple methods should be a baseline requirement.
Future rules should establish accuracy requirements for both false acceptances (minors falsely determined to be adults) and false rejections (adults falsely determined to be minors).
The New York rules require age assurance methods to meet accuracy standards for false acceptances and robustness standards against circumvention by minors. But they do not impose comparable standards for false rejections, which incentivizes covered operators to choose age assurance methods that are more likely to deny adults (and other eligible users) rightful access to age-gated features. In practice, covered operators need to balance access with the cost and operational complexity of offering multiple age assurance methods. It should not be assumed that compliance with the rules will naturally incentivize all covered platforms to make sufficiently accurate age assurance available.
The New York rules do require that false rejections be measured during certification and that covered operators offer users an appeal process to challenge incorrect determinations. Adding support for multiple methods and accuracy standards for false rejections would go further towards balancing availability with safety.
The rules establish performance standards and evaluation requirements for individual age assurance methods.
A strength of the rules is that they set concrete performance standards for individual age assurance methods and establish specific testing and annual third-party certification requirements for determining whether those standards are met. Method-level standards help ensure that covered operators do not rely on unproven, convenient, or easy-to-deploy approaches that perform poorly in practice. That is especially important where operators may offer users only one or two age assurance options, making the performance of each individual method consequential for whether users can successfully complete the process.
Future rules should be more comprehensive and precise about their measurement requirements.
In addition to individual method accuracy requirements, future rules should establish comparable end-to-end performance standards and evaluation requirements for the collection of methods offered by a covered provider. Doing so is critical because the accuracy of age assurance systems that route users across multiple methods cannot be inferred from evaluating individual methods alone. A system could rely on methods that each individually satisfy requirements while still performing poorly overall because of how those components interact in real-world use.
In addition to accuracy standards, the New York rules specify a quantitative circumvention detection threshold (98%). However, circumvention rates only make sense in the context of a specific set of circumvention techniques. Because some techniques are more effective than others, and defending against different techniques has different trade-offs when it comes to privacy and openness, any measurement of circumvention success inherently depends on the set of techniques tested and their frequency in the measurement set. For these reasons, future rules should use qualitative circumvention detection and mitigation standards that are incorporated into the certification process. These qualitative standards could require covered platforms to take appropriate steps to mitigate the most prevalent circumvention risks.
The rules create a strong accountability structure.
The rules recognize that effective age assurance requires more from covered operators than a one-time compliance check. They create a multilayered accountability structure in which covered operators are responsible for ongoing monitoring, accredited third parties provide independent certification, users can challenge incorrect classifications, and information about newly discovered circumvention techniques can come from outside the company and trigger further investigation. In this respect, New York’s governance structure allows covered operators to adapt their age assurance systems as they learn from implementation, and it creates mechanisms for accountability that do not rely solely on companies policing themselves.
The rules stand to generate a substantial amount of potentially useful information about how age assurance systems function in real-world deployments. Certification reports must document testing protocols and results, including false acceptance rates, false rejection rates, inconclusive outcomes, and circumvention testing. Covered operators must also retain some forms of data, such as monthly attempts by method and monthly denials related to circumvention.
Accountability documentation should be made available to the public.
Neither the certification reports nor operators’ ongoing evaluations are required to be made public. As a result, much of what companies and auditors learn about where age assurance succeeds, where it fails, and how it affects users will remain confined to the companies, the auditors, and the Attorney General’s office, leaving researchers, civil society, and the public unable to evaluate those findings for themselves.
That limitation matters because age assurance is still an emerging area of policy and practice, and implementation will itself generate evidence that could improve future rule updates, regulation, or technical system designs. If those results remain private, the public has little basis for assessing whether the rules are working, and independent researchers cannot contribute expert analysis to the AG’s enforcement of the rules. Future rules should require that certification reports include all data necessary for independent evaluation of age assurance systems, and that they be made public.
Conclusion
New York’s rules provide an important early model for translating age assurance mandates into concrete, enforceable requirements. As courts, regulators, and lawmakers confront the same implementation questions, they can build on the strengths of the New York rules while addressing their gaps – particularly around balancing access with other considerations, including privacy, service availability, and burdens on adult users; evaluating how age assurance systems perform as a whole; and enabling transparency and meaningful independent scrutiny. Getting these details right will be critical to having age assurance serve as an effective component of youth online safety rather than simply another compliance requirement.
Authors

